Export or back up the relevant data first. Do not delete, void, unreconcile, or adjust historical transactions unless you understand the accounting impact.
Menu names can change. We link current first-party instructions so you can confirm product behavior before acting.
Preserve the suspected period and reports before editing anything, define the question, restrict access if active misuse is possible, and use administrator access to filter the audit log by user, date, and event. Trace the affected transaction history and connected records, distinguish named users from system, banking, import, support, recurring, and integration activity, corroborate with external evidence, correct through an approved workflow, and document the control change.
Best for: administrators, accountants, reviewers, and business owners investigating unexpected QuickBooks activity
What this guide covers—and what it does not
The page owns one search intent: investigating QuickBooks Online user and system activity with the audit log. Related jobs have their own canonical guides so you can move between them without mixing product selection, setup, troubleshooting, and migration advice.
- This page owns QuickBooks Online audit-log use, evidence preservation, event interpretation, correction support, and access remediation.
- It does not prove who physically used a credential, intent, fraud, legal liability, or a complete forensic history.
- Security incidents, suspected crime, litigation, regulatory reporting, or material misstatement require qualified professional escalation.
Evidence-first workflow
Investigate without destroying the evidence
Preserve first, narrow the question, corroborate the event, and separate ledger correction from responsibility conclusions.
- 1
Contain
Preserve reports and evidence, assess active risk, and restrict compromised access without deleting records.
Evidence: The suspected population and response owner are defined.
- 2
Filter
Use date, user, and event filters and capture relevant transaction histories and indirect edits.
Evidence: The event set is reproducible.
- 3
Corroborate
Compare bank, source documents, approvals, integrations, email, access records, and affected reports.
Evidence: Facts are separated from assumptions.
- 4
Correct
Approve and perform the safest transaction-level correction with closed-period and reconciliation review.
Evidence: Ledger and downstream records are accurate.
- 5
Remediate
Fix access, workflow, integration, approval, monitoring, or training control failures.
Evidence: The root control gap has an owner and verification date.
Decision control
Choose from evidence, not a feature list
Use the same four gates for investigating QuickBooks Online user and system activity with the audit log: define the job, surface constraints, choose the smallest workable option, then verify the records.
Interpret common audit-log identities
Do not attribute an event to a person merely from a system-generated label or shared credential.
| Your situation | Direction | Why |
|---|---|---|
| Named company user | Corroborate access and source evidence | The log shows the account associated with the event, not necessarily the physical person or intent. |
| System Administration | Trace automation, recurring records, connected apps, and dependent changes | QuickBooks can create system events after user or automated activity. |
| Online Banking or Import Administration | Review feed, import, or migration history | The event may originate from a data pipeline rather than direct manual entry. |
| Support Representative or accounting firm | Check authorization and engagement records | Visibility and attribution differ between client, firm, and support contexts. |
Preserve state and define the investigation question
Export or save the affected financial reports, transaction detail, reconciliation reports, user list, connected-app list, relevant audit-log views, source documents, and external statements before correcting. Record time zone, date range, entity, accounts, transactions, users, and how the anomaly was detected.
If compromise or ongoing unauthorized activity is plausible, follow the incident process: secure administrator access, revoke or reduce access, rotate credentials through approved channels, review connected apps and bank permissions, and preserve evidence. Do not delete the suspected user or transaction merely to remove access.
Filter the log and interpret event context
Use the narrowest date, user, and event filters, then open transaction history. Record original and changed values, event time, transaction date, related customer/vendor, indirect edits, and nearby events. Intuit documents system-created users and a two-year availability period for Online activity; confirm current behavior and export needed evidence promptly.
Compare the log with recurring templates, imports, bank feeds, connected apps, accountant access, support sessions, and dependent transactions. A changed payment can create indirect changes to invoices, reconciliation, or reports.
Corroborate facts and correct the accounting separately
Tie the event to invoices, bills, receipts, approvals, bank or card statements, payroll records, emails, contracts, app logs, and access records available under policy. Mark each conclusion as confirmed, contradicted, unknown, or requiring specialist review.
Prepare a correction plan identifying accounts, customers/vendors, tax, projects, closed periods, reconciliations, reports, integrations, and filings affected. Obtain approval, preserve before-and-after evidence, make supported transaction-level changes, and rerun all affected reconciliations.
Do not accuse a person, publish personal data, or make a fraud conclusion from the QuickBooks audit log alone. Use legal, HR, security, forensic, insurance, or law-enforcement guidance where appropriate.
Turn the finding into a durable control improvement
Review user roles, accountant access, primary administrator ownership, shared credentials, multifactor authentication, connected apps, bank access, recurring templates, import rights, closing dates, approval evidence, and exception monitoring. Remove dormant access and reduce privileges to the minimum required.
Record incident timeline, scope, evidence, accounting correction, financial effect, notifications, root cause, owner, due date, and effectiveness test. Keep the sensitive case file under restricted retention rather than attaching it broadly to transactions.
Completion checklist
Do not call the decision or setup complete until someone independent of the initial change can verify these items.
Frequently asked questions
Can the QuickBooks audit log be turned off?
Intuit states that the QuickBooks Online audit log cannot be turned off. Confirm current product behavior and preserve relevant evidence within the documented availability period.
Does the audit log prove which employee changed a transaction?
It identifies the user or system identity associated with the event. Shared credentials, delegated access, integrations, and system actions mean additional evidence is needed to identify the physical actor and intent.
What does System Administration mean?
It can represent changes created automatically by QuickBooks, connected apps, recurring activity, bank feeds, or dependent changes. Trace the surrounding events and source system.
Still comparing adjacent tasks? Use the complete guide library to find the one page that owns your intent.
Sources checked
First-party product documentation used to verify the workflow and risk notes in this guide.